Assistant Manager Information Security

iFAST Global Bank Ltd

Greater London

On-site

GBP 70,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

iFAST Global Bank Ltd is seeking a senior governance-focused information security professional to maintain the ISMS, oversee data protection and resilience initiatives, and provide risk-focused reporting to senior management.

You will ensure security-by-design across initiatives, manage risk assessments, and coordinate with cyber security operations, data protection officers, and external providers to safeguard information assets.

Qualifications

  • Experience in information security governance, risk and compliance.
  • Strong knowledge of ISO 27001:2022 ISMS and security controls.
  • Experience with UK GDPR and data protection obligations.
  • Experience in incident response, business continuity and IT disaster recovery planning.
  • Familiarity with AWS cloud environments and security tooling.

Responsibilities

  • Maintain and continuously improve ISO 27001:2022 ISMS and related governance documents; ensure audit readiness.
  • Embed security-by-design and privacy-by-design in new initiatives and projects.
  • Conduct information security risk assessments and manage risk registers.
  • Define and adopt security controls for information flows across internal and external boundaries.
  • Serve as governance interface to security operations and liaise with technical teams.
  • Coordinate threat intelligence, vulnerability management and remediation SLAs.
  • Support testing of incident response, crisis management, and disaster recovery plans, including AWS environments.
  • Contribute to data protection governance, DPIAs, DSARs handling and DPIA records.

Skills

Information security
Risk assessment
Data protection
Regulatory compliance
Governance
Threat intelligence
Incident response
Disaster recovery
AWS Cloud

Tools

AWS Cloud
GRC tools

Job description

The role plays a vital role in safeguarding the bank's information assets and data, and in maintaining the governance frameworks that evidence a resilient and well-controlled security posture. The role is primarily focused on information / cyber security, data protection and resilience maintaining the ISO 27001:2022 Information Security Management System (ISMS), supporting the bank's data protection obligations and upkeeping cyber resilience, and providing management with timely, accurate and risk-focused reporting on the bank's security and compliance posture. The role proactively supports the bank's compliance with UK regulatory requirements, industry standards and best practice, while contributing to the development and enhancement of security and data protection frameworks, policies and controls. It also supports the bank's operational resilience; business continuity and IT disaster recovery arrangements. Drawing on strong analytical skills, sound knowledge of cyber security and data protection, and an understanding of the bank's security infrastructure (including AWS cloud environments), the role helps the bank maintain cyber and operational resilience, protect against financial and reputational risk, and foster a culture of sound security across the organisation.

MAIN DUTIES
  • Maintain and continuously improve the ISO 27001:2022 ISMS, including the Statement of Applicability, information security policies, standards and procedures, and the supporting documentation register, ensuring they remain current, mapped to control frameworks and audit-ready.
  • Provide proactive security and data protection assurance for new initiatives, change and ongoing projects, ensuring security-by-design and privacy-by-design requirements are embedded from design through implementation.
  • Conduct information security risk assessments to identify, evaluate and prioritise threats and control gaps, ensuring effective controls are agreed, implemented, tracked to closure and reflected in the risk register.
  • Define, document and drive adoption of security controls that protect information flows across internal systems, third parties and public networks, in line with the ISMS and regulatory requirements.
  • Act as the governance and oversight interface to the bank's cyber security operations, liaising with the specialist technical teams that run day-to-day security monitoring, detection and remediation, rather than performing these activities hands-on.
  • Conduct and coordinate threat intelligence and vulnerability management interpreting relevant intelligence, tracking identified vulnerabilities against remediation SLAs, coordinating timely remediation with technology teams and external providers, and keeping abreast of the evolving threat landscape.
  • Support the maintenance and testing of incident response and crisis management procedures, contributing to the effective triage, coordination and post-incident review of security and data protection events while minimising business disruption.
  • Act as support for the bank's operational resilience and business continuity arrangements, and working closely relevant stakeholders and IT on disaster recovery.
  • Conduct and contribute to business impact analyses, business continuity and IT disaster recovery plans and their testing (including the AWS cloud environment), helping ensure recovery objectives (RTO / RPO) are documented, achievable and evidenced, with lessons learned fed into improvements.
Data Protection Governance
  • Support the Data Protection Officer in operating the bank's data protection framework under UK GDPR and applicable regulations.
  • Maintain the Record of Processing Activities (ROPA) and support data retention, data minimisation and records-management governance across the bank.
  • Support the handling of Data Subject Access Requests (DSARs) and other data subject rights, and the completion of Data Protection Impact Assessments (DPIAs) for new or changed processing.
  • Assess personal data breaches, contributing to containment, root-cause analysis and the assessment of notification obligations to the ICO and affected individuals within regulatory timeframes.
  • Contribute to data protection and processor due diligence within third-party and outsourcing arrangements.
Third-Party & Supply Chain Security
  • Perform and govern security and data protection due diligence and ongoing assurance of suppliers, processors and critical third parties, in line with supplier controls and regulatory expectations on outsourcing and third-party risk.
  • Track third-party findings, remediation actions and assurance evidence (e.g. certifications, attestations, control reports), escalating material risks as appropriate.
Assurance, Compliance & Reporting
  • Partner with auditors, regulators and payment schemes by preparing evidence, providing subject-matter expertise, and supporting internal and external audits, certifications and reviews (including ISO 27001 surveillance and scheme assu)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager – Information Security
Assistant Manager – Information Security

Jobtailor • Greater London

Hybrid
GBP 70,000 - 95,000
Information Security Executive
Information Security Executive

iFAST Global Bank Limited • Greater London

Hybrid
GBP 50,000 - 70,000
Competitive salary
25 days annual leave plus bank holidays
Performance-based bonus
+4
Information Security and Data Protection Analyst
Information Security and Data Protection Analyst

Interact Software • Manchester

On-site
GBP 45,000 - 65,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
ICT Cyber and Information Security Manager
ICT Cyber and Information Security Manager

ISR RECRUITMENT LIMITED • Tees Valley

On-site
GBP 90,000 - 130,000
Head of Information Security and Privacy
Head of Information Security and Privacy

Morgan Law • Greater London

On-site
GBP 120,000 - 180,000
Data Security Lead
Data Security Lead

Barclays • Greater London

On-site
GBP 90,000 - 120,000
Information Security Manager
Information Security Manager

Hometrack • City Of London

On-site
GBP 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000